The most significant news in the launch of Muse is not that Meta has built a new artificial intelligence assistant. In 2026, assistants are everywhere. The real shift is that Meta is trying to turn agentic AI—systems that do not merely respond, but can take action across the digital world on the user's behalf—into a consumer product potentially aimed at hundreds of millions of people.
Muse, unveiled on September 8, is a personal agent capable of using a browser, working with connected services, filling out forms, booking travel, sending emails, carrying out tasks while the app is closed, and even making purchases. In the United States, it is rolling out on iOS, Android, and muse.ai, and can also be reached directly via WhatsApp. Meta says it will come to its AI glasses as well.
It is a shift in scale compared to the traditional chatbot. When a model produces a wrong answer, the harm may just be misinformation. When an agent has access to email, calendar, browser, and payments, a mistake can turn into a real-world action. That is why the most interesting aspect of the launch is not merely the model powering Muse, but the attempt to build rules, permissions, and guardrails around its actions.
From conversation to delegation
Muse is powered by Muse Spark, the family of models developed by Meta Superintelligence Labs. But the experience is designed to be different from a typical chat. Users can assign it a goal and let it get to work: the system can break down the task, open a browser, coordinate subtasks, and run in the background. Meta describes examples ranging from organizing a dinner party to selling a car, all the way to finding a better deal on a utility bill.
The difference is only seemingly subtle. A chatbot waits for the user to ask the next question. An agent, on the other hand, can maintain state, remember an objective, wait for an event, and decide when it is time to proceed. Muse can also send proactive messages when it believes there is something relevant to flag. In other words, software shifts from a tool that reacts to a collaborator that takes the initiative.
This is arguably the most significant direction for consumer AI in the coming years. Models are becoming capable enough to use existing software, but the real value emerges when they can cross different applications. Planning a trip does not just mean recommending a destination: it means searching for flights, comparing schedules, checking the calendar, filling in details, booking, and paying. Each step adds utility, but also introduces new risk surfaces.
Meta's edge is distribution
Meta enters a race in which OpenAI, Google, Anthropic, and numerous startups are already pushing agents toward computer and web use. But it holds an advantage that does not depend on benchmarks: distribution. WhatsApp, Instagram, Facebook, and Messenger are already places where billions of people communicate, shop, discover content, and organize parts of their lives.
If a personal agent is to become a habit, friction of access matters almost as much as the model's intelligence. Muse can be contacted just like messaging someone on WhatsApp. It is a strategic choice: rather than asking users to learn a new interface, Meta is attempting to weave the agent into an existing daily routine.
For now, the rollout is limited to the United States, so calling it a global product would be premature. But the potential is unmistakable. Agentic AI could stop being a power-user feature and become commonplace the moment it enters messaging apps.
Sentinel and the problem of control
Meta claims to have designed Muse around the assumption that an agent can make mistakes. It is an important premise. The system runs in a dedicated virtual machine and includes a separate component, called Sentinel, that monitors requests to external services and decides when an action should be authorized, blocked, or submitted for user confirmation.
The distinction is crucial because an assistant that can act must have stricter limits than a chatbot. For sensitive or hard-to-revert actions—such as sending an email or making a purchase—Muse must stop and ask for confirmation. Meta also states that passwords and payment methods are handled so that the agent can use them without having direct access to the full credentials.
This approach does not eliminate risks, but it points in a sensible direction: an agent's security cannot rely solely on the model "understanding" what is safe. External, verifiable, and predictable guardrails are needed—safeguards that remain in place even when the model misinterprets a situation.
The web is a hostile environment for an agent
An agent browsing online constantly reads content it does not control: pages, emails, documents, forms. Some may contain manipulative instructions or ambiguous information. That is why autonomous web usage is considered one of the most delicate areas of agentic AI.
Meta says it is addressing the issue by combining training, classification systems, environment isolation, human authorizations, and action limits. It has also included Muse in its public bug bounty program, with rewards of up to $300,000 for valid vulnerabilities.
The interesting point is not whether this makes Muse "safe" in an absolute sense—no complex system warrants such a promise—but that competition over agents is finally shifting part of the focus from benchmarks to boundary design.
When the agent can spend money
Muse also makes another transition tangible: agents are becoming economic actors. Meta has integrated Stripe Link to allow the agent to complete purchases on the user's behalf.
Stripe explains that, across more than one million businesses directly accepting Link, Muse can use the user's saved payment method. In other cases, Link can generate a single-use virtual card limited to the specific approved transaction. Before spending, the user must authorize the amount.
This is a technical detail with far broader implications. For years, e-commerce has been designed for humans browsing, comparing, and clicking “buy”. If agents start handling a portion of these actions, the way websites, stores, and payment systems are built will also change. It will no longer be enough to be human-readable: platforms will need to be queryable and trustworthy for software acting on their behalf.
It also opens up a question of liability. If an agent buys the wrong product, agrees to unfavorable terms, or misinterprets a request, who actually made the decision? The legal and commercial answer will increasingly depend on the quality of consent mechanisms, activity logs, and the ability to reconstruct exactly what the user authorized.
The privacy promise is ambitious
Meta knows that the main hurdle for Muse isn't its ability to fill out a form. It is convincing people to entrust it with intimate information and access to personal services. That is why privacy sits at the core of the launch.
The company states that Muse conversations and data within its virtual machine are not shared with Meta's advertising systems, and that users can opt out of having their interactions used for model training. These are significant commitments, especially considering the sheer amount of context a personal agent can accumulate.
Meta has also announced a version called Muse Confidential VM, scheduled for later in 2026, which is designed to use encryption strong enough to prevent even the company itself from reading the contents of the user's personal environment. It is a promise that will need to be verified once the system is live, but it signals how much privacy is becoming a competitive feature for agents.
Trust becomes a product feature
With chatbots, trust was primarily epistemic: “can I believe this answer?”. With agents, it becomes operational: “can I let this software do something in my place?”. That is a much higher bar.
To clear it, an agent must be competent, but also predictable. It needs to show what it is doing, ask for permission at the right times, remember without becoming invasive, use credentials without exposing them, and stop when the risk is too high. A system that prompts for confirmation on every click becomes unusable; one that never asks becomes dangerous. Product quality will lie in the middle.
Meta seems to have realized that this balance is not an interface detail, but the core of the experience. Muse displays an activity log, offers permission controls, and decouples sensitive approvals from the conversation. It is a sensible direction, even if the definitive test will only come with real-world use at scale.
Why Muse matters even if it isn't available in Italy today
Muse matters because it shows what artificial intelligence's next dominant interface could look like. Chat made talking to a model feel natural. The agent attempts to make delegating a piece of one's digital life feel natural.
If this paradigm succeeds, competition will no longer be solely about who builds the model with the top benchmark. What will matter is the agent's operating system, permissions, payments, integrations, memory, security, ability to sustain long-horizon work, and above all, the trust users are willing to grant it.
Meta occupies a unique position: it simultaneously controls models, a massive distribution network, and products that already hold a major share of people's digital relationships and behaviors. It is an extremely powerful combination, but also one that invites the strictest scrutiny on privacy.
The question, then, is not whether Muse is “smarter” than ChatGPT, Gemini, or Claude. The question is whether people will be willing to hand an agent enough context and enough agency to make it genuinely useful. Because agentic AI carries a straightforward paradox: the more it can do for us, the more it needs to know about us, and the more we must trust the guardrails preventing it from doing the wrong thing.
With Muse, Meta is attempting to solve both halves of the problem within the same product. If it pulls it off, the transition from chatbots to agents will no longer be a tech enthusiast demo. It could become a daily habit.



